I also don't leave any information I'm worried about someone stealing in my Google account. I find it hard to understand how anyone in tech could fail to see how risky that is.
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
491–500 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#492Earlier quoted context omitted.
How can he spoof an email address without Gmail or the like flagging it? I'm not talking about the common name but the actual email address.
That's what I'm curious about too. DMARC should make that impossible.
Supposedly, people have been fired after being falsely accused of harassment. The scam works as follows:
Send a message to bob@gappsdomain.com and notavictim at the same domain. Arrange for the headers to be “from” bob. Now, notavictim reports Bob to HR. If the google admin is competent, they look at the headers, and note that Bob didn’t send the email. (Not sure if they catch the offender or not.)
If they’re incompetent, they see the message in Bob’s from box, and recommend he be fired.
This is a feature that enables dubious workflows, where Bob configures spam bots to bother his coworkers, but wants those messages to be auto filed in his sent box.
I didn’t think it worked when spoofing unrelated domains like Google though. That’s just dumb. Maybe the attacker had the author’s IMAP gateway password and moved the message into the inbox?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#493Earlier quoted context omitted.
Gotcha, thanks for clarifying! And did you have passwords using chrome password manager as well (which were also compromised by the Google account access, and this is how they got access to e.g. Coinbase?), or did they get passwords through some other means and just needed 2FA?
I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used in the past. And then they opened up Google's Authenticator app, signed in as me, and got the auth code for Coinbase. By enabling cloud-sync, Google has created a massive security vulnerability for the entire industry. A developer can't be…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#494I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…
but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#495Earlier quoted context omitted.
Just wondering what is the plan in case this thing you have gets lost? And would you say that using something like authy with encryption using a totally unique password is safe?
Typically you print out recovery codes and keep them somewhere safe
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#496Never share a verification code. Scammers use urgency and fear (“you must resolve this in the next hour”) to get you to act.
Based on the second warning, I've decided not to trust the first.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#497Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#498Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#499Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#500How is this basic fail still possible?